Skip to content

fix(core): default to Ryuk 0.14.0, which doesn't break concurrent image pulls - #1131

Open
thirtyseven wants to merge 1 commit into
testcontainers:mainfrom
thirtyseven:fix/ryuk-default-0.14
Open

thirtyseven wants to merge 1 commit into
testcontainers:mainfrom
thirtyseven:fix/ryuk-default-0.14

Conversation

@thirtyseven

Copy link
Copy Markdown

Ryuk 0.8.1 cleans up each session with ImagesPrune filtered to the session label. On the containerd image store, the default since Docker 29, the daemon's ImagePrune deletes every in-flight pull's lease before applying the filter (moby/moby#53321). So every test session that ends corrupts the image pulls of every other process on the same daemon, which fail with lease does not exist, failed commit on ref or failed to extract layer. On a CI runner with a few hundred testcontainers sessions a day this was a steady source of flaky pulls.

Ryuk 0.10.0+ removes images one at a time with ImageRemove and never calls ImagesPrune. This bumps the default to 0.14.0 and updates the docs.

Reproduction (Docker 29.8.1, containerd snapshotter): start a large uncached docker pull, then let a testcontainers session end while it runs. With Ryuk 0.8.1 the pull fails with failed to extract layer … failed to Lchown; with 0.14.0 it completes. A filtered prune that matches nothing breaks the pull the same way:

docker pull python:3.12.7 &
sleep 4
docker image prune -f --filter label=org.testcontainers.session-id=does-not-exist
wait   # → failed to extract layer (…): … no such file or directory

Newer Ryuk logs msg=Started instead of Started!. On main the startup wait doesn't run yet, and #1124 changes the pattern to \bStarted\b, so this PR doesn't touch it. With #1124 merged on top, tests/core/test_ryuk.py passes (8 tests) against real Docker with Ryuk 0.14.0. Without it, test_wait_for_reaper fails the same way on 0.8.1 as on 0.14.0 on a Linux docker-proxy host (#1114: Ryuk never receives the session filter).

🤖 Generated with Claude Code

…ge pulls

Ryuk 0.8.1 cleans up each session with ImagesPrune filtered to the
session label. On the containerd image store, the default since Docker 29,
the daemon's ImagePrune deletes every in-flight pull's lease before it
applies the filter (moby/moby#53321). Each test session that ends
therefore corrupts the image pulls of every other process on the same
daemon, which fail with "lease does not exist", "failed commit on ref"
or "failed to extract layer". Ryuk 0.10.0 and later remove images one at
a time with ImageRemove and never call ImagesPrune.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant